CVE-2016-2164

Description

The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the Java URL class without checking the specified protocol handler, which allows remote attackers to read arbitrary files by attempting to upload a file.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
1.232

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-2163,CVE-2016-2164 are fixed in Apache - openmeetings-parent 3.1.1Windows
Vulnerabilities CVE-2016-2163,CVE-2016-2164 are fixed in Apache - openmeetings-parent for Linux 3.1.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234